Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.008exploits catalogados
34.638CVEs com exploração pública
24.695testados em laboratório
13.743 exploits
GitHub PoC
h1bAna/CVE-2017-5123
CVE-2017-512311 mar 2023
Insufficient data validation in waitid allowed an user to escape sandboxes on Linux.
23RISCO
abrir
GitHub PoC
ahiahai242/CVE-2017-5123
CVE-2017-512311 mar 2023
Insufficient data validation in waitid allowed an user to escape sandboxes on Linux.
23RISCO
abrir
GitHub PoC15
This is poc of CVE-2022-46169 authentication bypass and remote code execution
CVE-2022-46169CRITICALsob ataque11 mar 2023
Unauthenticated Command Injection
100RISCO
abrir
GitHub PoC1
Laravel RCE CVE-2021-3129
CVE-2021-3129CRITICALsob ataqueransomware11 mar 2023
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir
GitHub PoC
python 2.7
CVE-2023-23752MEDIUMsob ataque11 mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir
GitHub PoC11
Tomcat PUT方法任意文件写入(CVE-2017-12615)exp
CVE-2017-12615HIGHsob ataqueransomware10 mar 2023
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISCO
abrir
GitHub PoC
Microsoft Word 远程代码执行漏洞
CVE-2023-21716CRITICAL10 mar 2023
Microsoft Word Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC
FortiRecorder Denial of Service Exploit (CVE-2022-41333)
CVE-2022-41333MEDIUM10 mar 2023
An uncontrolled resource consumption vulnerability [CWE-400] in FortiRecorder version 6.4.3 and below, 6.0.11 and below
33RISCO
abrir
GitHub PoC2
Tenda f3 Malformed HTTP Request Header Processing Vulnerability.
CVE-2020-35391CRITICAL09 mar 2023
Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_pas
60RISCO
abrir
GitHub PoC4
Open Web Analytics 1.7.3 - Remote Code Execution
CVE-2022-2463709 mar 2023
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, wh
60RISCO
abrir
GitHub PoC4
SSH User Enumerator in Python3, CVE-2018-15473, I updated the code of this exploit (https://www.exploit-db.com/exploits/45939) to work with python3 instead of python2.
CVE-2018-15473MEDIUM09 mar 2023
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
GitHub PoC4
CVE-­2021­-1732 Microsoft Windows 10 本地提权漏 研究及Poc/Exploit开发
CVE-2021-1732HIGHsob ataqueransomware09 mar 2023
Windows Win32k Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC135
Windows LPE exploit for CVE-2022-37969
CVE-2022-37969HIGHsob ataque09 mar 2023
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISCO
abrir
GitHub PoC7
Bulk scanner + get config from CVE-2023-23752
CVE-2023-23752MEDIUMsob ataque09 mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir
GitHub PoC2
开源,go多并发批量探测poc,准确率高
CVE-2023-23752MEDIUMsob ataque09 mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir
GitHub PoC2
CVE-2019-15107 图形化测试程序
CVE-2019-15107CRITICALsob ataqueransomware09 mar 2023
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir
GitHub PoC2
CVE-2022-47986: Python, Ruby, NMAP and Metasploit modules to exploit the vulnerability.
CVE-2022-47986CRITICALsob ataqueransomware09 mar 2023
IBM Aspera Faspex code execution
100RISCO
abrir
GitHub PoC
sei-fish/CVE-2021-22205
CVE-2021-22205CRITICALsob ataqueransomware09 mar 2023
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISCO
abrir
GitHub PoC7
Mass Auto Exploit CVE-2022-4395 Unauthenticated Arbitrary File Upload
CVE-2022-4395CRITICAL09 mar 2023
Membership For WooCommerce < 2.1.7 - Unauthenticated Arbitrary File Upload
53RISCO
abrir
GitHub PoC
Results of retrohunt for files matching YARA rules from https://github.com/AmgdGocha/Detection-Rules/blob/main/CVE-2023-21716.yar
CVE-2023-21716CRITICAL08 mar 2023
Microsoft Word Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC59
A vulnerability within Microsoft Office's wwlib allows attackers to achieve remote code execution with the privileges of the victim that opens a malicious RTF document. The attacker could deliver this file as an email attachment (or other means).
CVE-2023-21716CRITICAL08 mar 2023
Microsoft Word Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC
rahmadsandy/EXIM-4.87-CVE-2019-10149
CVE-2019-10149CRITICALsob ataque07 mar 2023
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISCO
abrir
GitHub PoC
adriyansyah-mf/CVE-2023-23752
CVE-2023-23752MEDIUMsob ataque07 mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir
GitHub PoC46
RTF Crash POC Python 3.11 Windows 10
CVE-2023-21716CRITICAL07 mar 2023
Microsoft Word Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC4
FeatherStark/CVE-2023-21716
CVE-2023-21716CRITICAL07 mar 2023
Microsoft Word Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC8
spring cloud function 一键利用工具! by charis 博客https://charis3306.top/
CVE-2022-22963CRITICALsob ataque07 mar 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISCO
abrir
GitHub PoC
Script in Ruby for the CVE-2022-35914 - RCE in GLPI
CVE-2022-35914CRITICALsob ataque07 mar 2023
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
100RISCO
abrir
GitHub PoC1
Pada bulan maret 2023, terdapat sample baru yang terindentifikasi sebagai malware. Malware tersebut berasal dari file berekstensi.xls dan .doc dan dikenal dengan nama “Bank Slip.xls”. Aktivitas malware tersebut memiliki hubungan dengan kerentanan yang dikenal dengan id CVE-2017-11882 dan CVE-2018-0802.
CVE-2017-11882HIGHsob ataqueransomware06 mar 2023
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISCO
abrir
GitHub PoC1
Pada bulan maret 2023, terdapat sample baru yang terindentifikasi sebagai malware. Malware tersebut berasal dari file berekstensi.xls dan .doc dan dikenal dengan nama “Bank Slip.xls”. Aktivitas malware tersebut memiliki hubungan dengan kerentanan yang dikenal dengan id CVE-2017-11882 dan CVE-2018-0802.
CVE-2018-0802HIGHsob ataque06 mar 2023
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow
93RISCO
abrir
GitHub PoC2
CVE-2022-31814
CVE-2022-31814CRITICAL05 mar 2023
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RISCO
abrir
anteriorpágina 280 / 459próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.